What is NIST?
NIST—the U.S. National Institute of Standards and Technology—publishes widely used security and digital identity guidance. For identity teams, the NIST SP 800‑63 suite defines assurance levels for identity proofing, authentication, and federation. It explains what “good” looks like: evidence strength, fraud resistance, authenticator requirements, and lifecycle controls.
How this lands in product: set Level of Assurance targets by feature, demand phishing‑resistant factors where value spikes, and document why thresholds exist. For remote onboarding, use high‑quality document checks, selfie‑to‑ID match, and spoof resistance that meets the intent of the framework ‑ see identity verification and liveness checks. For authentication, favor hardware‑backed methods over shared secrets.